Incomplete List of Disallowed Inputs in Nexus Repository Manager - CVE-2026-77124

 

Incomplete List of Disallowed Inputs in Nexus Repository Manager - CVE-2026-77124

Published: September 7, 2026


Vulnerability identifier: #VU147238
CSH Severity: Low
CVSS v4: 7.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-77124
CWE-ID: CWE-184
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute previously created scripts.

The vulnerability exists due to an incomplete list of disallowed inputs in the script execution endpoint when processing requests to run stored scripts after script execution has been disabled. A remote privileged user can invoke the script execution endpoint to execute previously created scripts.

Only instances where the Script API was previously enabled and stored scripts already exist are affected.


Affected software

Nexus Repository Manager

How to mitigate CVE-2026-77124

Install security update from vendor's website.

Nexus Repository Manager - update to 3.96.0-09

External References

Related Security Bulletins